|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Mon Jan 25 2010 - 17:11:10 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----------------------------------------------------------------------
Secunia integrated with Microsoft WSUS
http://secunia.com/blog/71/
----------------------------------------------------------------------
TITLE:
Apache Tomcat 5 WAR Deployment Directory Traversal Weaknesses and
Security Issue
SECUNIA ADVISORY ID:
SA38346
VERIFY ADVISORY:
http://secunia.com/advisories/38346/
DESCRIPTION:
Some weaknesses and a security issue have been reported in Apache
Tomcat, which can be exploited by malicious users and malicious
people to manipulate certain data, and by malicious people to gain
access to potentially sensitive information.
An error within the autodeployment functionality may lead to deployed
files with improper access restrictions and missing input validation
when deploying WAR files can be exploited to e.g. delete files within
the host's work directory or create arbitrary files outside of the web
root.
For more information:
SA38316
The weaknesses and the security issue are reported in version 5.5.0
to 5.5.28.
SOLUTION:
Fixed in the SVN repository. Reportedly, this will be fixed in the
upcoming version 5.5.29.
http://svn.apache.org/viewvc?rev=902650&view=rev
ORIGINAL ADVISORY:
http://tomcat.apache.org/security-5.html
1)
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0476.html
2)
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0478.html
3)
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0477.html
OTHER REFERENCES:
SA38316:
http://secunia.com/advisories/38316/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]